Live data from Hacker News

NSA OSS Technologies

nationalsecurityagency.github.io

51–60 of 114 posts

Re: NSA OSS Technologies

#51
post #12

This caught my eye: > https://github.com/apache/incubator-pirk > Employing homomorphic encryption techniques, PIR enables datasets to remain resident in their native locations while giving the ability to query the datasets with sensitive terms. I can imagine a few scenarios there. One perhaps is when db admin should not find out what someone, possibly working on a classified project is querying. Or say one compartmen…

This is pretty common in the commercial world too, and something I've done more than once myself. The obvious use case is storing medical records. In the UK personal medical records are often stored by systems integrators in datacentres with nebulous locations, and need to be accessed by third parties for things like underwriting life insurance policies. To protect the data (compliance with the EU data protection act…

Are AMRAs kinda like "stored procedures" then?

Re: NSA OSS Technologies

#52
post #48

Fun sidenote: I was the very first civilian to contribute to their GitHub project back in July 2015, when SIMP was the only project they had up on GitHub. It was literally a one letter change in the README file, but I still have the privilege to call myself the very first civilian to contribute to the NSA's open source project: https://github.com/NationalSecurityAgency/SIMP/pull/1

I'd shake your hand

Re: NSA OSS Technologies

#53
post #21

Violating the sanctity of the captive portal license agreement! https://github.com/iadgov/goSecure/blob/master/scripts/wifi_... :)

The captive portal license agreement?

That code just bypasses a captive portal. It's basically automatically clicking "I agree".

Re: NSA OSS Technologies

#54
That's nice to see the NSA is contributing to the OSS community. I just randomly picked one of the NSA GitHub repositories, analysed it with VersionEye (https://www.versioneye.com) and found already 25 security vulnerabilities. Who is the best person to contact in this case? Here is the security report: https://www.versioneye.com/user/projects/59479cd06725bd00123....

Re: NSA OSS Technologies

#55
Femto (https://github.com/femto-dev/femto) looks pretty interesting to me just based on some work I've needed to do in the past that it would've come in handy for.

It looks like the last commit was over a year ago, though. Is there information I'm not seeing of whether these projects are actively maintained (or still in use at NSA?).

Re: NSA OSS Technologies

#56

Earlier quoted context omitted.

This is pretty common in the commercial world too, and something I've done more than once myself. The obvious use case is storing medical records. In the UK personal medical records are often stored by systems integrators in datacentres with nebulous locations, and need to be accessed by third parties for things like underwriting life insurance policies. To protect the data (compliance with the EU data protection act…

Are AMRAs kinda like "stored procedures" then?

AMRAs are like physical documents with an instruction to the information guardian, with a signature from the information owner, authorising access.

A lot of it is electronic these days, and is automated to the point that an individual authorises access by clicking a link in an email that calls an endpoint that in turn releases a token and URL to the requestor to view the appropriate records.

Re: NSA OSS Technologies

#58

Why are people so welcoming to the filthy spies invading citizen privacy?

I really don't understand it, to be honest I think it's unbelievable. I'd say we, as in the IT community, shouldn't touch anything coming out of the NSA with a 10 feet pole, even if we're absolutely sure it's not some kind of morally dubious attack tool.

Fuck the NSA!

Re: NSA OSS Technologies

#59
post #48

Fun sidenote: I was the very first civilian to contribute to their GitHub project back in July 2015, when SIMP was the only project they had up on GitHub. It was literally a one letter change in the README file, but I still have the privilege to call myself the very first civilian to contribute to the NSA's open source project: https://github.com/NationalSecurityAgency/SIMP/pull/1

great job collaborating with what is, in essence; the American version of the Stasi.

Re: NSA OSS Technologies

#60
post #54

That's nice to see the NSA is contributing to the OSS community. I just randomly picked one of the NSA GitHub repositories, analysed it with VersionEye ( https://www.versioneye.com ) and found already 25 security vulnerabilities. Who is the best person to contact in this case? Here is the security report: https://www.versioneye.com/user/projects/59479cd06725bd00123... .

They say it clearly themselves:

> The government benefits from the open source community’s enhancements to the technology.

They're hoping that by putting this code out there, unwitting dupes will then collaborate with them to contribute to the surveillance state.

Post reply on HN